Vendor Scorecard
The procurement checklist, pre-filled and signed
Most security and procurement teams ask the same 60 questions. We answer all of them in advance, sign the file, and version it on the trust ledger. Use it as-is or import into your own framework.
Overall score
95%
21 of 22 fully met
Frameworks mapped
6
SIG, CAIQ, ISO, SOC 2, NIST, EU AI Act
Average completion
< 1 day
vs industry 4–6 weeks
Last signed
2026-06-25
By CISO + CFO
Answered checklist
| Area | Question | Answer |
|---|---|---|
| Security | SOC 2 Type II current within 12 months | Yes |
| Security | ISO 27001:2022 certified | Yes |
| Security | Independent penetration test in last 12 months | Yes |
| Security | Bug bounty program active | Yes |
| Security | Customer-managed encryption keys | Partial |
| Security | Zero-trust architecture documented | Yes |
| Privacy | GDPR data processing addendum available | Yes |
| Privacy | Subprocessor list public + 30d notice | Yes |
| Privacy | EU data residency option | Yes |
| Privacy | DPIA template provided | Yes |
| Financial | Audited financial statements | Yes |
| Financial | Cash runway > 24 months | Yes |
| Financial | Customer funds segregated | Yes |
| Operational | 99.95% uptime SLA with credits | Yes |
| Operational | Incident response < 30 min MTTR | Yes |
| Operational | Backup tested in last 30 days | Yes |
| AI governance | EU AI Act self-assessment published | Yes |
| AI governance | Model cards for each AI feature | Yes |
| AI governance | Human-in-the-loop on material decisions | Yes |
| Exit | Full data export in open formats | Yes |
| Exit | Export deliverable within 24 hours | Yes |
| Exit | Contractual exit assistance period | Yes |